@2ffa8eb4 Isn't this worse that the current state of things? At the moment I have a large LUKS password in my brain. But instead the password will be stored inside a sketchy chip. Am I misunderstanding how this works? I'll know if I'm forced to leak the key, where as the TPM might leak it if it's an evil one.
Honest question:
Why should we trust our TPM's to store a secret? What proves the chip maker, U.S. government, or whoever else doesn't have a backdoor API or method to get them to give up our private key?
https://www.youtube.com/watch?v=0RSH3JXqShE
/cc @2ffa8eb4
What happens if my laptop motherboard dies, and I want to move my harddrive to a new computer? What happens if I want to use a bootable Fedora USB key to debug something on the main system? How do I unlock the disk?
Notes by 8825ea4f | export